6 ms·
hi the author of the vuln here. this is my write up http://intothesymmetry.blogspot.ch/2016/01/openssl-key-recovery-attack-on-dh-small.html http://intothesymmet
by asanso 11y ago
hi the author of the vuln here. this is my write up http://intothesymmetry.blogspot.ch/2016/01/openssl-key-recovery-attack-on-dh-small.html http://intothesymmetry.blogspot.ch/2016/01/openssl-key-recov...
- jvehent 11y agoThanks for the excellent description of the vuln! You mention Apache not being vulnerbale. I just looked through the Nginx code, and it doesn't seem to be vulnerable either because Igor Sysoev enabled SSL_OP_SINGLE_DH_USE back in 2008. https://github.com/nginx/nginx/blob/master/src/event/ngx_event_openssl.c#L250 https://github.com/nginx/nginx/blob/master/src/event/ngx_eve...
- asanso 11y agoindeed. but there is always Static DH :) even if not so popular...
- jvehent 11y agoOps teams need a clear "should I do emergency patching? yes/no" message when any vulnerability gets published. In this instance, it looks like this doesn't require emergency patching unless you're using something unusual to terminate SSL. That said, it's a serious issue, no doubt about that.
- blakesterz 11y agoI struggle with this sometimes too! So often I read the report and I'm left wondering if I should panic or not, so I start reading comments here and elsewhere to figure out if I need to get this patched OMG RIGHT NOW or I can hold off until the weekend. I would LOVE a clear "should I do emergency patching? yes/no" it seems like it would be frequently (maybe not always?) something that could be added to an announcement.
- jvehent 11y agoThat's what your local security team should be for ;) At Mozilla, we track those and inform the various ops teams of our assessments. They very much rely on us to decide if it warrants emergency patching or not (modulo operational concerns to upgrade systems outside maintenance windows).
- detaro 11y agoNot so great an option if the closest thing to a "local security team" is the sysadmin asking the question ;)
- tokenizerrr 11y agoThat's great. Now what about smaller companies which have one, maybe two sysadmins?
- sarciszewski 11y agoThis is a good point. I'll be sure to put that at the top of any vulnerabilities I report in the future.
- kroeckx 11y agoI tried to be clear in when you're vulnerable and when not, so that you can decide if you're vulnerable or not. The answer in this case is "it depends, very likely not".
- dang 11y agoOk, let's change the URL to that from https://mta.openssl.org/pipermail/openssl-announce/2016-January/000061.html https://mta.openssl.org/pipermail/openssl-announce/2016-Janu.... An author's writeup counts as the original source, and people always like to find out how it was done.